CVE-2026-64405
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can be NULL while req_status is still HCI_REQ_PEND, leading to a NULL pointer dereference and a general protection fault from the hci_rx_work() receive path.
Instead of inspecting hdev->sent_cmd, track the in-flight create connection command with a new per-connection HCI_CONN_CREATE flag and route all cancellation through hci_cancel_connect_sync(), which dispatches to a dedicated per-type cancel function.
Leer descripción completaMostrar menos
The create command is in exactly one of two states: still queued, or in flight. The cancel function holds cmd_sync_work_lock across the whole decision: the worker takes this lock to dequeue every entry, so while it is held a queued command cannot start running and an in-flight command cannot complete and let the next command become pending. This keeps the flag test and hci_cmd_sync_cancel() atomic with respect to the worker, so a queued command is simply dequeued, and an in-flight command owned by this connection is cancelled without the risk of cancelling an unrelated command that became pending in the meantime. CIS uses the same flag mechanism via HCI_CONN_CREATE_CIS but cannot be dequeued per-connection.
hci_acl_create_conn_sync() and hci_le_create_conn_sync() clear HCI_CONN_CREATE after the create command completes, but the command status handler can free conn via hci_conn_del() (for example when the controller rejects the connection) while the worker is still blocked on the connection complete event. Hold a reference on conn across the create command so the flag can be cleared without a use-after-free.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a
- https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348
- https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819
- https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2
- https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0
- https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64405",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6083089ab00631617f9eac678df3ab050a9d837a",
"lessThan": "903227b6168bb99fd57d4e3c9c1b5014986198e0",
"versionType": "git"
},
{
"status": "affected",
"version": "a13f316e90fdb1fb6df6582e845aa9b3270f3581",
"lessThan": "83b22d7f7c384564fa42c3cf19bec715c693d7a2",
"versionType": "git"
},
{
"status": "affected",
"version": "a13f316e90fdb1fb6df6582e845aa9b3270f3581",
"lessThan": "70c397b62ee015e19b3924d9da741c8dda017819",
"versionType": "git"
},
{
"status": "affected",
"version": "a13f316e90fdb1fb6df6582e845aa9b3270f3581",
"lessThan": "61701912c58a05f6a043f097cc177a964abef348",
"versionType": "git"
},
{
"status": "affected",
"version": "a13f316e90fdb1fb6df6582e845aa9b3270f3581",
"lessThan": "b42cb640a0493d16b61ddd267420274be15efdc1",
"versionType": "git"
},
{
"status": "affected",
"version": "a13f316e90fdb1fb6df6582e845aa9b3270f3581",
"lessThan": "12917f591cea1af36087dba5b9ec888652f0b42a",
"versionType": "git"
},
{
"status": "affected",
"version": "e4511a67fcdba9729d1c7cfc6d2e645c765ce801",
"versionType": "git"
},
{
"status": "affected",
"version": "4ab81f16c68a602b2b69e333ae08d8748a9398de",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.83",
"lessThan": "6.1.118",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.4.16",
"lessThan": "6.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.5.3",
"lessThan": "6.6",
"versionType": "semver"
}
],
"programFiles": [
"include/net/bluetooth/hci_core.h",
"net/bluetooth/hci_conn.c",
"net/bluetooth/hci_sync.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.118",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/net/bluetooth/hci_core.h",
"net/bluetooth/hci_conn.c",
"net/bluetooth/hci_sync.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-25T10:17:24.110",
"references": [
{
"url": "https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()\n\nhci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection\nwas pending, but hdev->sent_cmd can be NULL while req_status is still\nHCI_REQ_PEND, leading to a NULL pointer dereference and a general\nprotection fault from the hci_rx_work() receive path.\n\nInstead of inspecting hdev->sent_cmd, track the in-flight create\nconnection command with a new per-connection HCI_CONN_CREATE flag and\nroute all cancellation through hci_cancel_connect_sync(), which\ndispatches to a dedicated per-type cancel function. The create command\nis in exactly one of two states: still queued, or in flight. The cancel\nfunction holds cmd_sync_work_lock across the whole decision: the worker\ntakes this lock to dequeue every entry, so while it is held a queued\ncommand cannot start running and an in-flight command cannot complete\nand let the next command become pending. This keeps the flag test and\nhci_cmd_sync_cancel() atomic with respect to the worker, so a queued\ncommand is simply dequeued, and an in-flight command owned by this\nconnection is cancelled without the risk of cancelling an unrelated\ncommand that became pending in the meantime. CIS uses the same flag\nmechanism via HCI_CONN_CREATE_CIS but cannot be dequeued per-connection.\n\nhci_acl_create_conn_sync() and hci_le_create_conn_sync() clear\nHCI_CONN_CREATE after the create command completes, but the command\nstatus handler can free conn via hci_conn_del() (for example when the\ncontroller rejects the connection) while the worker is still blocked on\nthe connection complete event. Hold a reference on conn across the\ncreate command so the flag can be cleared without a use-after-free."
}
],
"lastModified": "2026-09-04T15:30:19.823",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "581FAE92-2FB9-4713-97A0-8CB7D8E34AA9",
"versionEndExcluding": "6.1.118",
"versionStartIncluding": "6.1.83"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5099559-2D15-42A5-A561-71B34FEFF36F",
"versionEndExcluding": "6.5",
"versionStartIncluding": "6.4.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA70A1F0-2178-430A-862F-E9CE20CA69CC",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.5.3"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05880CF6-5AD2-44E9-853A-6CE8318E76A5",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E8B9085-7ADB-4A05-89EF-12949B6A0509"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FC0D50D-9D58-4947-A197-A5A3FF07E7E3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}